https://www.puppet.com/community logo
Join Slack
Powered by
# voxpupuli
  • v

    VoxBot

    11/07/2024, 6:38 PM
    and we germans are a step ahead and the Government dismantled itself yesterday :D
    😁 2
  • v

    VoxBot

    11/07/2024, 6:46 PM
    binford2k: ikr :(
  • v

    VoxBot

    11/07/2024, 6:50 PM
    someone pointed towards this in another channel. I guess that would be the basis of the "security" argument in the blog post? https://adnanthekhan.com/2024/07/02/roguepuppet-a-critical-puppet-forge-supply-chain-vulnerability/
  • v

    VoxBot

    11/07/2024, 6:52 PM
    yup. Except that the vuln was a new Pune engineer who didn't take the time to understand the giant "don't use this" warning on docs for a github trigger. Now everyone who mitigated that problem is gone, and they're shipping all puppet dev work to..... Pune
    sadpanda 3
  • v

    VoxBot

    11/07/2024, 6:55 PM
    what's Pune?
  • v

    VoxBot

    11/07/2024, 6:55 PM
    Pune, India
  • v

    VoxBot

    11/07/2024, 6:56 PM
    ah I see
  • v

    VoxBot

    11/07/2024, 6:57 PM
    so it sounds like we're gonna be moving on the upstream packaging real soon now https://overlookinfratech.com/2024/10/31/flutter-forking/
  • v

    VoxBot

    11/07/2024, 7:07 PM
    wow.. the vuln-post was a piece of interesing reading..
    πŸ‘ 1
    ☝️ 1
  • v

    VoxBot

    11/07/2024, 7:16 PM
    https://woodruffw.github.io/zizmor/ + https://github.com/synacktiv/octoscan might have helped there :)
  • v

    VoxBot

    11/07/2024, 7:21 PM
    100% ⬆️
  • v

    VoxBot

    11/07/2024, 7:22 PM
    I was working on said things when we parted ways
  • v

    VoxBot

    11/07/2024, 7:24 PM
    but it's interesting, that GH is such a big vector
  • v

    VoxBot

    11/07/2024, 7:25 PM
    (I might have broken Ansible Galaxy using it in the past whistle https://www.die-welt.net/2021/11/getting-access-to-somebody-elses-ansible-galaxy-namespace/)
  • v

    VoxBot

    11/07/2024, 7:25 PM
    vuln vector? Or factor in this announcement?
  • v

    VoxBot

    11/07/2024, 7:25 PM
    I mean… it obviously is a vector, but in more ways than "this hosts all our jewels"
  • v

    VoxBot

    11/07/2024, 7:25 PM
    vuln vector
  • y

    Yury Bushmelev

    11/08/2024, 7:11 AM
    Oh wow! I missed a lot yesterday :)
  • s

    saz

    11/08/2024, 7:43 AM
    I'd be happy to missed some of those things πŸ™‚
  • y

    Yury Bushmelev

    11/08/2024, 7:56 AM
    yeah..
  • y

    Yury Bushmelev

    11/08/2024, 7:58 AM
    all the concerns above are valid.. I'd add that I see no reason to use EULA'ed packages for 25 machines if there are community packages available (and are good enough). Which brings me to the question.. who are the users of this developer subscription/EULA at all? Why the hell to suffer with all the T&C just to have 25 OSS packages?
  • y

    Yury Bushmelev

    11/08/2024, 7:59 AM
    s/packages\?$/machines with "official" packages/
  • y

    Yury Bushmelev

    11/08/2024, 8:00 AM
    that idea is only viable if there are no community packages or those packages are bad in many ways (e.g. fragmented or some tooling (PDK) cannot be used with them)
  • y

    Yury Bushmelev

    11/08/2024, 8:01 AM
    which leads me to really dark thoughts
  • y

    Yury Bushmelev

    11/08/2024, 8:02 AM
    BUT.. Puppet will die w/o community very quickly.. it'll become PE-only and will be used in just few places.. then Perforce will sell it away/kill it because it worth no money paid to the developers and managers.
  • y

    Yury Bushmelev

    11/08/2024, 8:03 AM
    sooo... I hope there is 1-2 effective managers who want to pull as much money as possible before being fired who doing this
  • y

    Yury Bushmelev

    11/08/2024, 8:05 AM
    though.. there is one more reason I can foresee.. but it's conspirology mostly πŸ™‚
  • r

    ripienaar

    11/08/2024, 8:25 AM
    They are not going to be pushing code changes to public repos regularly. So community packages will be sub par to their own and not have the same features.
    d
    • 2
    • 1
  • r

    ripienaar

    11/08/2024, 8:26 AM
    So instead the more likely outcome is a fork and not community providing packages imo - or just death of the community
  • y

    Yury Bushmelev

    11/08/2024, 8:26 AM
    fork means someone else will sell it.. not Perforce.. πŸ™‚
1...623624625...648Latest